# Security audit CONFIRMED IN CODE unless noted. - Vault `ApiKeyVault` for `sand_` / `prod_` - Public REST nonce + rate limits + circuit breaker - `LogRedactor` — no secretKey in public config - `BookingPayloadGuard` on CPT - HMAC inbound **default off** - GDPR exporters do not cancel Nuitee bookings - Capabilities: Agency Staff cannot edit bookings / vault / purge - Live: HTTPS; LiteSpeed; WP Hide Security Enhancer plugin present (**config UNKNOWN**) - Homepage exposes a personal Gmail on tour cards (**PII hygiene issue**, CONFIRMED LIVE) - Plugin license: NOT FOUND - No invented certifications